CVE-2025-27907
CVSS 3.1 Score 4.1 of 10 (medium)
Details
Published Apr 22, 2025
Updated: Apr 23, 2025
CWE ID 918
Summary
CVE-2025-27907 is a newly identified vulnerability affecting IBM WebSphere Application Server versions 8.5 and 9.0. This issue permits authenticated attackers to execute server-side request forgeries (SSRF), enabling them to send unauthorized requests from the system. The potential consequences of this vulnerability include network enumeration and facilitation of further attacks. IBM urges users to install the available patches or updates to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- IBM WebSphere Application Server
Affected Vendors
- IBM